Method, device and equipment for tenant resource management and medium

By defining resource types and delivery types in multi-tenant scenarios and establishing an association between tenants and resource templates, the problem of resource recovery failure is solved, rapid resource recovery and flexible control are achieved, and resource allocation efficiency is improved.

CN120639602APending Publication Date: 2025-09-12QIANSAN (BEIJING) TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510639290.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-16
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

In a multi-tenant scenario, once a resource is delegated to different roles of each tenant, it cannot be quickly recovered.

Method used

By creating resource nodes and resource templates, defining resource types and resource delivery types, establishing an association between tenants and target resource templates, and configuring the resource delivery type to be invisible, you can implement logical resource control switches and achieve rapid resource recovery.

Benefits of technology

It achieves rapid resource recovery and flexible control, improves resource allocation efficiency, meets the diverse needs of different tenants, and reduces the risk of permission management vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639602A_ABST
    Figure CN120639602A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of multi-tenant resource management, and discloses a tenant resource management method, device, equipment and medium, the method comprises the following steps: creating resource nodes, the resource nodes comprising a resource type and a resource issuing type, creating a resource template, the resource template comprising multiple types of resource nodes; establishing an association relationship between the tenant and a target resource template, and allocating resources to the tenant based on a resource issuing type of each resource node in the target resource template, the resource issuing type of each resource node in the target resource template including invisible; if the resource issuing type of the resource node in the target resource template is invisible and the resource node corresponding to the invisible resource is not issued, the resource issuing type is configured to be invisible under the condition that the target resource is issued to different roles of each tenant and the use of the target resource needs to be stopped, so that the rapid recovery of the resource can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of multi-tenant resource management, and in particular to a method, apparatus, device and medium for tenant resource management. Background Art

[0002] With the development of cloud computing and software-as-a-service models, multi-tenant architectures have become widely adopted in enterprise applications. In a multi-tenant architecture, multiple tenants use the same software system, each with independent data and business processes. Tenant resource permission control has become a key technology for ensuring data security and business independence for each tenant. Currently, the Role-Based Access Control (RBAC) model is widely used in the permission management field. It uses roles as an intermediary to associate users with resource permissions, simplifying the permission management process.

[0003] However, in a multi-tenant scenario, when enterprises manage tenant resource configurations and tenants manage internal employee resource permissions, once a resource is delegated to different roles of each tenant, if the resource needs to be completely stopped, it cannot be quickly reclaimed. Summary of the Invention

[0004] In view of this, the present invention provides a method, apparatus, device and medium for tenant resource management to solve the problem that in a multi-tenant scenario, once a resource is delegated to different roles of each tenant, if the resource needs to be stopped completely, the resource cannot be quickly recovered.

[0005] In a first aspect, the present invention provides a method for tenant resource management, the method comprising: creating a resource node, the resource node comprising a resource type and a resource delivery type, creating a resource template, the resource template comprising a plurality of types of resource nodes; establishing an association relationship between a tenant and a target resource template, and allocating resources to the tenant based on the resource delivery type of each resource node in the target resource template, wherein the resource delivery type of each resource node in the target resource template comprises invisible; if the resource delivery type of the resource node in the target resource template is invisible, the resource node corresponding to the invisible is not delivered.

[0006] In an optional embodiment, the resource delivery type of each resource node in the target resource template also includes visible to all or visible to tenant administrators; if the resource delivery type of the resource node in the target resource template is visible to all, the access rights of the resource nodes corresponding to the visible to all are allocated to each role in the tenant; if the resource delivery type of the resource node in the target resource template is visible to the tenant administrator, the access rights of the resource nodes corresponding to the visible to the tenant administrator are allocated to the tenant administrator.

[0007] In an optional embodiment, the aforementioned method for tenant resource management also includes: creating a preset role, the preset role including multiple types of resource nodes, and configuring the default state of the preset role to be disabled; if the target tenant switches the preset role from the disabled state to the enabled state, assigning the preset role to the target tenant; assigning the resource usage rights corresponding to the preset role to employees in the target tenant, wherein the employees do not have the rights to edit the resources corresponding to the preset role.

[0008] In an optional embodiment, the aforementioned method for tenant resource management further includes: if the preset role is switched from the enabled state to the disabled state, the preset role is changed to a self-created role, and the permission to edit the resources corresponding to the self-created role is assigned to the employee.

[0009] In an optional implementation, the aforementioned method for tenant resource management further includes: creating a self-built role, and determining resource usage permissions corresponding to the self-built role based on an association relationship between the tenant and the target resource template.

[0010] In an optional implementation, the aforementioned method for tenant resource management further includes: if the tenant creates a target employee, allocating the resource usage rights corresponding to the preset role or the resource usage rights corresponding to the self-created role to the target employee.

[0011] In an optional implementation, the aforementioned method for tenant resource management further includes: modifying the resource delivery type based on the needs of the tenant.

[0012] In a second aspect, the present invention provides a device for tenant resource management, the device comprising: a first module for creating a resource node, the resource node comprising a resource type and a resource delivery type, creating a resource template, the resource template comprising a plurality of types of resource nodes; a second module for establishing an association relationship between a tenant and a target resource template, and allocating resources to the tenant based on the resource delivery type of each resource node in the target resource template, wherein the resource delivery type of each resource node in the target resource template comprises invisible; a third module for not delivering the corresponding invisible resource node if the resource delivery type of each resource node in the target resource template is invisible.

[0013] In a third aspect, the present invention provides a computer device comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, computer instructions being stored in the memory, and the processor executing the method for tenant resource management of the first aspect or any corresponding embodiment thereof by executing the computer instructions.

[0014] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the method for tenant resource management of the above-mentioned first aspect or any corresponding embodiment thereof.

[0015] In a fifth aspect, the present invention provides a computer program product comprising computer instructions for causing a computer to execute the method for tenant resource management according to the first aspect or any corresponding embodiment thereof.

[0016] The method, apparatus, device and medium for tenant resource management provided by the present invention define resource nodes through the dual attributes of resource type and resource delivery type, can realize the logical control switch of resources through the resource delivery type, create resource templates through multiple types of resource nodes, form a reusable resource configuration scheme based on the resource template, and realize template-driven operation and maintenance automation; the establishment of the association relationship between tenants and target resource templates can realize a many-to-many mapping relationship between tenants and resource templates in a multi-tenant scenario; when the target resource is delivered to different roles of each tenant and it is necessary to stop using the target resource, the resource delivery type is configured to be invisible, so that the resource can be quickly recovered. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in related technologies, the following briefly introduces the drawings required for use in the specific embodiments or related technical descriptions. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0018] Figure 1 A schematic diagram showing a flow chart of a method for tenant resource management according to an embodiment of the present invention is shown;

[0019] Figure 2 Another schematic diagram of a method for tenant resource management provided by an embodiment of the present invention is shown;

[0020] Figure 3 A schematic structural diagram of an apparatus for tenant resource management according to an embodiment of the present invention is shown;

[0021] Figure 4Schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0022] To make the purpose, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of the present invention.

[0023] Related technologies use the H-RRBAC model to allocate resource permissions and control access, generating a user's resource permission tree to implement user access control. Alternatively, based on the RBAC model, permissions management can be made scalable and configurable by maintaining the relationships between users, roles, permissions, and sessions.

[0024] For enterprises managing multiple tenants, the methods used in related technologies struggle to flexibly and efficiently meet the diverse resource needs of different tenants. Resource allocation and permission settings lack sufficient flexibility and scalability. For example, if a resource needs to be taken offline or reclaimed, it's impossible to quickly reclaim the resource for all users.

[0025] When tenants manage resource permissions for internal employees, the existing technologies are often overly complex or imprecise, unable to quickly adapt to the dynamic changes in employee roles and responsibilities. This leads to inefficient resource allocation, prone to permissions management loopholes, and inability to meet the diverse resource needs of different employees. For example, if a resource requires full role assignment, all resource-application bindings must be modified, resulting in inefficient operations.

[0026] The following is an introduction to the concepts involved in the present invention. Role-Based Access Control (RBAC) is a method for controlling user access to resources by assigning permissions to roles. In the present invention, it is used for resource permission management in multi-tenant scenarios. Software-as-a-Service (SaaS) is a model for providing software services over the Internet. The method for tenant resource management provided by the present invention can be applied to multi-tenant management scenarios of SaaS platforms.

[0027] According to an embodiment of the present invention, a method embodiment for tenant resource management is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0028] This embodiment provides a method for tenant resource management, which can be used in multi-tenant management scenarios of SaaS platforms. Figure 1 A flow chart of a method for tenant resource management according to an embodiment of the present invention is shown. Figure 1 As shown, the process includes the following steps:

[0029] Step S101: creating a resource node, which includes a resource type and a resource delivery type; and creating a resource template, which includes multiple types of resource nodes.

[0030] In this step, the resource node is the smallest logical unit of resource management in the multi-tenant architecture of the SaaS platform. The attributes of a resource node include resource type, resource delivery type, parent node of the resource node, and resource identification information. The resource node is represented based on the resource identification information, and the parent resource of the resource node is represented based on the parent node of the resource node. Resource nodes can be presented in a tree structure. Enterprise users can create all resource nodes in the tenant management backend. Resource types include menus, pages, or buttons.

[0031] Resource template attributes include a name and various types of resource nodes. Enterprise users create resource templates by specifying a name and selecting the resource nodes included in the template in the resource tree, establishing a one-to-many (1:N) relationship between the template and the resource nodes.

[0032] Specifically, taking an enterprise operating a SaaS platform with multiple tenants using the platform for business management as an example, step S101 is explained.

[0033] Enterprise administrators perform the following operations in the tenant system management backend: First, create a resource node. For example, to create a menu resource node, the enterprise administrator enters the menu name, uses the menu name as resource identification information, and represents the created menu resource node based on the menu name. Select the parent menu as the resource node's parent node. Set the resource type to Menu. Based on business needs, determine the resource delivery type, which can be Invisible, Visible to All, or Visible to Tenant Administrators. If the menu resource node is customized for a specific tenant, the resource delivery type can be set to "Visible to Tenant Administrators."

[0034] Next, you can create a resource template called "Basic Business Template." On the resource tree, select the menu, page, and button resources required for basic business operations to complete the configuration of the resource template and resource nodes.

[0035] Step S102: establishing an association relationship between the tenant and the target resource template, and allocating resources to the tenant based on the resource delivery type of each resource node in the target resource template, wherein the resource delivery type of each resource node in the target resource template includes invisible.

[0036] In this step, you can establish associations between the target tenant and multiple resource templates, or between multiple tenants and the target resource template. You can use a label selector or a policy engine to establish mappings between tenants and target templates, allowing multiple tenants to share the same resource template.

[0037] Enterprise users associate tenants with target resource templates. The system allocates resources to tenants based on the resource delivery type of each resource node. Resource nodes with an invisible resource delivery type are not delivered.

[0038] Specifically, tenants bind resource templates, for example, by establishing an association between a tenant and a "Basic Business Template." The system then allocates resources to the tenant based on the resource node's resource delivery type. If a resource node's resource delivery type is "Visible to All," all roles within the tenant can access the resource; if it's "Visible to Tenant Administrators," only the tenant administrator can access it.

[0039] Step S103: If the resource delivery type of the resource node in the target resource template is invisible, the resource node corresponding to the invisible resource is not delivered.

[0040] In this step, by configuring the resource node's resource delivery type to invisible, the resource node remains invisible even if a tenant delivers the resource node. This solves the problem of not being able to quickly reclaim a resource if it needs to be decommissioned after it has been delivered to different tenant roles.

[0041] The method for tenant resource management provided in this embodiment defines resource nodes through the dual attributes of resource type and resource delivery type. The logical control switch of resources can be realized through the resource delivery type, and resource templates are created through multiple types of resource nodes. A reusable resource configuration plan is formed based on the resource template. Enterprise users can maintain the tree relationship of resource node data and the association relationship between resource templates and resource nodes in the tenant management background, and can realize template-driven operation and maintenance automation; the establishment of the association relationship between tenants and target resource templates can realize a many-to-many mapping relationship between tenants and resource templates in a multi-tenant scenario; when the target resource is delivered to different roles of each tenant and it is necessary to stop using the target resource, the resource delivery type is configured as invisible, which can realize rapid resource recovery.

[0042] There is also a problem in the related technology that if a resource needs to be decentralized to all tenants and all roles, a new resource node needs to be added to each tenant and each role, resulting in low resource decentralization efficiency and inability to quickly decentralize resources.

[0043] In some optional implementations, the resource delivery type of each resource node in the target resource template also includes visible to all or visible to tenant administrators; if the resource delivery type of the resource node in the target resource template is visible to all, the access rights of the corresponding resource nodes visible to all are assigned to each role in the tenant; if the resource delivery type of the resource node in the target resource template is visible to tenant administrators, the access rights of the corresponding resource nodes visible to tenant administrators are assigned to the tenant administrators.

[0044] In this embodiment, the resource delivery type is configured to include both visible to all and visible to tenant administrators. Changing the resource delivery type to visible to all makes the resource node visible to all roles, even if the tenant has not delegated the resource node. Changing the resource delivery type to visible to tenant administrators adjusts the access permissions of the resource node, allowing only tenant administrators to access the resource node.

[0045] This allows enterprises to flexibly control tenant resource permissions, while tenants can efficiently manage employee resource permissions. Furthermore, different resource delivery types can be used to precisely allocate tenant resources.

[0046] In related technologies, for industries with fixed role divisions, roles need to be configured one by one, resulting in low resource allocation efficiency.

[0047] In some optional embodiments, the aforementioned method for tenant resource management also includes: creating a preset role, the preset role includes multiple types of resource nodes, and configuring the default state of the preset role to be disabled; if the target tenant switches the preset role from a disabled state to an enabled state, the preset role is assigned to the target tenant; and the resource usage rights corresponding to the preset role are assigned to employees in the target tenant, wherein the employees do not have the permission to edit the resources corresponding to the preset role.

[0048] In this implementation, enterprise users create a pre-configured role by specifying the role name and identifying the resource nodes accessible to the pre-configured role in the resource tree, establishing a one-to-many relationship between the pre-configured role and the resource nodes. Once a pre-configured role is created, it is disabled by default. When the pre-configured role is enabled, the system copies the pre-configured role data for each tenant, and tenant employees cannot edit the assigned pre-configured role.

[0049] Specifically, when creating a preset role, you can create a "normal employee preset role" and in the resource tree, you can check the resource nodes required by the preset role in business operations, for example, the menus and pages that the preset role can access in business operations. For buttons that the preset role cannot access, do not check the resource nodes corresponding to the buttons that the preset role cannot access. When the normal employee preset role is enabled, the normal employee preset role data is copied for each tenant. When a tenant creates an employee, he or she can directly bind the normal employee preset role. The employee obtains the corresponding resource permissions and cannot edit the normal employee preset role.

[0050] This way, when pre-configured roles are enabled, the pre-configured role data is automatically replicated for each tenant. By creating, disabling, and enabling pre-configured roles, tenants can quickly configure resource permissions for their employees. Furthermore, by configuring different pre-configured roles, the diverse resource requirements of tenant employees can be met, significantly reducing the cost of controlling employee resources.

[0051] In some optional implementations, the aforementioned method for tenant resource management further includes: if the preset role is switched from an enabled state to a disabled state, the preset role is changed to a self-created role, and the permission to edit the resources corresponding to the self-created role is assigned to the employee.

[0052] In this embodiment, when a preset role changes from enabled to disabled, the preset role corresponding to each tenant is changed to a tenant-created role. Employees in the tenant can edit the tenant-created role based on actual business needs.

[0053] This allows for the flexibility of resource node permission management by enabling, disabling, and converting pre-configured roles, as well as tenant-created roles. Furthermore, if the status of a pre-configured role changes, the permissions associated with the resource node can be flexibly adjusted.

[0054] In some optional implementations, the aforementioned method for tenant resource management further includes: creating a self-built role, and determining resource usage permissions corresponding to the self-built role based on an association relationship between the tenant and the target resource template.

[0055] In this embodiment, both the tenant administrator role and the preset role in the tenant can create tenant-built roles. The resource node selection range of the self-built role includes the resource nodes in the target resource template associated with the tenant.

[0056] Specifically, if some employees within a tenant have special business needs, you can create tenant-defined roles, such as "Business Development Customized Roles." When selecting resource nodes, you can only select the resource nodes required by the Business Development Customized Role from the target resource templates associated with the tenant.

[0057] In this way, by limiting the selection of resource nodes for tenants' self-built roles, the standardization and security of permission management are guaranteed, preventing employees from arbitrarily obtaining resource permissions that exceed business needs.

[0058] In some optional implementations, the aforementioned method for tenant resource management further includes: if the tenant creates a target employee, allocating resource usage permissions corresponding to a preset role or a self-created role to the target employee.

[0059] In this embodiment, when a tenant creates an employee in the system, the tenant can select a self-created role or a preset role for the employee, and the selected role determines the resource permissions that the employee has.

[0060] Specifically, when a tenant creates a new employee and assigns a role to the new employee, they can select "Pre-set role for general employee" or "Self-built role for business expansion" based on the new employee's responsibilities. The new employee will then have the resource permissions corresponding to the selected role and can carry out business operations normally.

[0061] In this way, pre-configured roles support one-click batch assignment, reducing the workload of repeated configuration, and self-built roles support on-demand customization of permission combinations to meet differentiated needs. At the same time, it can improve the efficiency of resource permission management.

[0062] In some optional implementations, the aforementioned method for tenant resource management further includes: modifying the resource delivery type based on tenant needs.

[0063] In this embodiment, the resource delivery type can be adjusted based on the actual resource allocation needs. The resource delivery type can be modified to invisible, and even if the tenant delivers the resource, the resource will not be visible; the resource delivery type can be modified to fully visible, and even if the tenant does not deliver the resource, the resource will be visible to all roles.

[0064] In this way, resources can be quickly recovered or quickly decentralized, improving resource allocation efficiency.

[0065] Figure 2 Another schematic diagram of the method for tenant resource management provided by an embodiment of the present invention is shown. Figure 2 As shown, the method for user tenant resource management includes a tenant system management backend 21 and a tenant system end 22. In the tenant system management backend 21, the following operations are performed:

[0066] In step S211, the enterprise user creates a resource. The resource includes a type, a parent node, an identifier, and a distribution type. Among them, the type includes a menu, a page, and a button. The parent node includes the parent resource of the resource. The identifier is used to uniquely identify the resource. The distribution type includes invisible, visible to all, and visible to tenant administrators.

[0067] Step S212: Create a resource template, fill in the template name and configure resources, wherein the configured resources can select the resources owned by the template.

[0068] Step S213: Create a preset role, fill in the template name and configure resources, wherein the configured resources can select the resources owned by the preset role.

[0069] On tenant system 22:

[0070] Step S221, establish an association relationship between the tenant and the resource template, and allocate resources to the tenant based on the resource delivery type. If the resource delivery type is invisible, the resource will not be delivered; if the resource delivery type is visible to all, the resource will be delivered to all roles in the tenant; if the resource delivery type is visible to tenant administrators, the resource will be delivered to the tenant administrator in the tenant.

[0071] Step S222: If the target tenant switches the preset role from disabled to enabled, the preset role is assigned to the target tenant; if the target tenant switches the preset role from enabled to disabled, the preset role is changed to a self-created role. At the same time, the tenant administrator role in the target tenant can also create a self-created role.

[0072] This allows enterprise users to quickly and easily create resources, resource templates, and pre-configured roles, as well as bind tenants to resource templates, improving the efficiency of managing tenant resource configuration. Furthermore, by configuring different resource templates, enterprise users can flexibly control resource permissions, meeting the diverse resource needs of different tenants.

[0073] This embodiment also provides a device for tenant resource management, which is used to implement the above-mentioned embodiments and preferred implementations. Details that have already been described will not be repeated. As used below, the term "module" may refer to a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation using hardware, or a combination of software and hardware, is also possible and contemplated.

[0074] This embodiment provides a device for tenant resource management. Figure 3 A schematic diagram of the structure of a device for tenant resource management according to an embodiment of the present invention is shown. Figure 3 Shown, including:

[0075] The first module 301 is used to create a resource node, which includes a resource type and a resource delivery type, and to create a resource template, which includes multiple types of resource nodes.

[0076] The second module 302 is used to establish an association relationship between the tenant and the target resource template, and allocate resources to the tenant based on the resource delivery type of each resource node in the target resource template, wherein the resource delivery type of each resource node in the target resource template includes invisible.

[0077] The third module 303 is configured to: if the resource delivery type of each resource node in the target resource template is invisible, not deliver the corresponding resource node.

[0078] In some optional implementations, the second module 302 includes:

[0079] The first unit of the second module is used to assign the access rights of the corresponding resource nodes that are visible to all to each role in the tenant if the resource delivery type of the resource node in the target resource template is visible to all; if the resource delivery type of the resource node in the target resource template is visible to the tenant administrator, assign the access rights of the corresponding resource nodes that are visible to the tenant administrator to the tenant administrator.

[0080] In some optional implementations, the aforementioned apparatus for tenant resource management further includes:

[0081] The fourth module is used to create preset roles. The preset roles include multiple types of resource nodes. The default state of the preset roles is configured to be disabled. If the target tenant switches the preset role from disabled to enabled, the preset role is assigned to the target tenant. The resource usage permissions corresponding to the preset role are assigned to employees in the target tenant, where employees do not have the permission to edit the resources corresponding to the preset role.

[0082] In some optional implementations, the aforementioned apparatus for tenant resource management further includes:

[0083] The first unit of the fourth module is used to switch the preset role from an enabled state to a disabled state, change the preset role to a self-created role, and assign the permission to edit the resources corresponding to the self-created role to the employee.

[0084] In some optional implementations, the aforementioned apparatus for tenant resource management further includes:

[0085] The fifth module is used to create a self-built role and determine the resource usage permissions corresponding to the self-built role based on the association relationship between the tenant and the target resource template.

[0086] In some optional implementations, the aforementioned apparatus for tenant resource management further includes:

[0087] The first unit of the fifth module is used to assign resource usage permissions corresponding to preset roles or self-created roles to target employees if a tenant creates a target employee.

[0088] In some optional implementations, the aforementioned apparatus for tenant resource management further includes:

[0089] The sixth module is used to modify the resource delivery type based on tenant needs.

[0090] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.

[0091] The device for tenant resource management in this embodiment is presented in the form of a functional unit, where the unit refers to an application-specific integrated circuit (ASIC) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.

[0092] The embodiment of the present invention also provides a computer device having the above Figure 3 An apparatus for tenant resource management is shown.

[0093] See also Figure 4 , Figure 4 is a structural diagram of a computer device provided by an optional embodiment of the present invention, such as Figure 4 As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components utilize different buses to communicate with each other and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in or on the memory to display the graphical information of a graphical user interface on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Equally, multiple computer devices can be connected, and each device provides part of the necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 4 A processor 10 is taken as an example.

[0094] The processor 10 may be a central processing unit, a network processor, or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic, or any combination thereof.

[0095] The aforementioned memory 20 stores instructions that can be executed by at least one processor 10, so that the aforementioned at least one processor 10 executes the method shown in the above embodiment.

[0096] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created based on the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely located relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0097] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid-state drive; the memory 20 may also include a combination of the above types of memory.

[0098] The computer device further includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30 and the output device 40 may be connected via a bus or other means. Figure 4 The bus connection is taken as an example.

[0099] The input device 30 can receive input digital or character information and generate key signal input related to user settings and function control of the computer device, such as a touch screen, a keypad, a mouse, a trackpad, a touch pad, an indicator stick, one or more mouse buttons, a trackball, a joystick, etc. The output device 40 can include a display device, an auxiliary lighting device (such as a light emitting diode) and a tactile feedback device (such as a vibration motor). The above-mentioned display device includes but is not limited to a liquid crystal display, a light emitting diode, a display and a plasma display. In some optional embodiments, the display device can be a touch screen.

[0100] The embodiment of the present invention also provides a computer-readable storage medium. The above-mentioned method according to the embodiment of the present invention can be implemented in hardware, firmware, or implemented as a computer code that can be recorded in a storage medium, or implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor or hardware, the method shown in the above embodiment is implemented.

[0101] A portion of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the form in which the computer program instruction exists in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc. Accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium that can be accessed by the computer.

[0102] Although the embodiments of the present invention have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention. Such modifications and variations are all within the scope defined by the appended claims.

Claims

1. A method for tenant resource management, characterized in that: The method comprises: Creating a resource node, the resource node including a resource type and a resource delivery type, and creating a resource template, the resource template including multiple types of resource nodes; Establishing an association relationship between a tenant and a target resource template, and allocating resources to the tenant based on a resource delivery type of each resource node in the target resource template, wherein the resource delivery type of each resource node in the target resource template includes invisible; If the resource delivery type of the resource node in the target resource template is invisible, the resource node corresponding to the invisible is not delivered.

2. The method according to claim 1, characterized in that The resource delivery type of each resource node in the target resource template also includes visible to all or visible to tenant administrators; If the resource delivery type of the resource node in the target resource template is "all visible", the access rights of the resource node corresponding to "all visible" are allocated to each role in the tenant; If the resource delivery type of the resource node in the target resource template is visible to the tenant administrator, the access permission for the corresponding resource node to be visible to the tenant administrator is allocated to the tenant administrator.

3. The method according to claim 1 or 2, characterized in that The method further comprises: Creating a preset role, the preset role including multiple types of resource nodes, and configuring the default state of the preset role to be a disabled state; If the target tenant switches the preset role from the disabled state to the enabled state, assigning the preset role to the target tenant; Allocate resource usage permissions corresponding to the preset role to employees in the target tenant, wherein the employees do not have permissions to edit resources corresponding to the preset role.

4. The method according to claim 3, characterized in that The method further comprises: If the preset role is switched from the enabled state to the disabled state, the preset role is changed to a self-created role, and the permission to edit the resources corresponding to the self-created role is allocated to the employee.

5. The method according to claim 3, characterized in that The method further comprises: A self-built role is created, and based on the association relationship between the tenant and the target resource template, the resource usage permission corresponding to the self-built role is determined.

6. The method according to claim 5, characterized in that The method further comprises: If the tenant creates a target employee, the resource usage rights corresponding to the preset role or the resource usage rights corresponding to the self-created role are allocated to the target employee.

7. The method according to claim 1, characterized in that The method further comprises: Based on the needs of the tenant, the resource delivery type is modified.

8. A device for tenant resource management, characterized in that: The device comprises: The first module is used to create a resource node, which includes a resource type and a resource delivery type, and create a resource template, which includes multiple types of resource nodes; The second module is used to establish an association relationship between a tenant and a target resource template, and allocate resources to the tenant based on the resource delivery type of each resource node in the target resource template, wherein the resource delivery type of each resource node in the target resource template includes invisible; The third module is configured to, if the resource delivery type of each resource node in the target resource template is invisible, not deliver the resource node corresponding to the invisible one.

9. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the method for tenant resource management according to any one of claims 1 to 7 by executing the computer instructions.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the method for tenant resource management according to any one of claims 1 to 7.

Citation Information

Cited By

  • Resource creation method applied to cloud service, electronic equipment, storage medium and program product

    CN121396774A

  • Multi-tenant resource processing method, device and equipment

    CN122293746A